source audit

Kevin Fenzi kevin at scrye.com
Fri Aug 24 16:34:17 UTC 2007


On Fri, 24 Aug 2007 11:03:07 -0400
matt at truch.net (Matthew D Truch) wrote:

> In the case of gpsd, your file reports:
> 
> BAD_CVS_SOURCE:gpsd-2.34.tar.gz:gpsd
> 
> But gpsd-2.34.tar.gz is not in cvs, it's in the lookaside cache.  And
> furthermore, the md5sum between the file in the lookaside cache
> matches the file pointed to by the Source: URL in the spec file.  
> 

Yeah, this is a false positive/error. 

When my script ran this is what I got from a spectool -g: 

--13:52:29--  http://download.berlios.de/gpsd/gpsd-2.34.tar.gz
           => `./gpsd-2.34.tar.gz'
Resolving download.berlios.de... 195.37.77.141
Connecting to download.berlios.de|195.37.77.141|:80... connected.
HTTP request sent, awaiting response... 302 Moved Temporarily
Location:
http://download.berlios.de/error/HTTP_SERVICE_UNAVAILABLE.html.var
[following] --13:52:29--
http://download.berlios.de/error/HTTP_SERVICE_UNAVAILABLE.html.var =>
`./HTTP_SERVICE_UNAVAILABLE.html.var' Connecting to
download.berlios.de|195.37.77.141|:80... connected. HTTP request sent,
awaiting response... 200 OK Length: unspecified [text/html]

    0K .                                                        16.34
MB/s

Last-modified header missing -- time-stamps turned off.
13:52:30 (16.34 MB/s) - `./HTTP_SERVICE_UNAVAILABLE.html.var' saved
[1058]

I will try and correct things to detect this and not report it. 

Sorry for the noise. 

kevin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/fedora-devel-list/attachments/20070824/adc27637/attachment.sig>


More information about the fedora-devel-list mailing list